Jobs · Information Technology · Missouri

Synergies between DORA and GDPR: A comprehensive approach to data security

Information TechnologyInternship

Introduction

The European Union's Regulation (EU) 2022/2554 mandates financial institutions to enhance their digital operational resilience through the Digital Operational Resilience Act (DORA). This regulation consolidates and harmonizes sector-specific European regulations and directives, applying to banking, investment companies, leasing, private equity, asset management, insurance, and central banks.

Key Requirements of DORA

  • Develop and implement robust strategies and procedures for managing information and communication technology (ICT) risks.

  • Introduce state-of-the-art security measures to protect IT systems and data.

  • Report significant ICT incidents to the competent authorities within defined deadlines.

  • Maintain strict controls over third-party service providers providing critical IT services.

  • Regularly conduct resilience tests, including penetration tests and simulations.

Interfaces Between DORA and GDPR

Protection of Personal Data

  • DORA and GDPR both require robust security measures to protect data integrity and confidentiality.

  • Both regulations mandate the introduction of security measures to safeguard personal data against unauthorized access, loss, or misuse.

Notification of Security Incidents

  • DORA requires financial organisations to report significant ICT security incidents to supervisory authorities within a short timeframe.

  • The GDPR obliges companies to report data breaches resulting in a risk to the rights and freedoms of natural persons to supervisory authorities within 72 hours.

Risk Management

  • DORA and GDPR both require comprehensive ICT risk management to identify, assess, and manage risks, including those affecting personal data.

  • Data protection impact assessments (DPIAs) are required for processing operations posing a high risk to natural persons' rights and freedoms under GDPR.

Technical and Organizational Measures (TOMs)

  • Financial companies must implement suitable technical and organizational measures to ensure the resilience of their IT systems.

  • Companies must take technical and organizational measures to ensure a minimum level of protection for personal data appropriate to the risk.

Controls and Audits

  • Regular review and auditing of ICT risk management and security processes are required under both DORA and GDPR.

  • Companies must regularly review compliance with data protection regulations and conduct data protection audits.

Summary

The interfaces between DORA and GDPR highlight their shared goals of ensuring data integrity, confidentiality, and availability. While DORA focuses on operational resilience and IT security in the financial sector, GDPR emphasizes the protection of personal data. An integrated approach that considers both IT security and data protection aspects is essential for effective compliance with both regulations.

Author

Regina Mühlich, Managing Director of AdOrga Solutions GmbH; Member of the Board of the Professional Association of Data Protection Officers in Germany (BvD) e.V.

Similar jobs